CVE-2010-5298Race Condition in Openssl

Severity
4.0MEDIUMNVD
EPSS
10.7%
top 6.65%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 14
Latest updateMay 14

Description

Race condition in the ssl3_read_bytes function in s3_pkt.c in OpenSSL through 1.0.1g, when SSL_MODE_RELEASE_BUFFERS is enabled, allows remote attackers to inject data across sessions or cause a denial of service (use-after-free and parsing error) via an SSL connection in a multithreaded environment.

CVSS vector

AV:N/AC:H/C:N/I:P/A:PExploitability: 4.9 | Impact: 4.9

Affected Packages8 packages

Debianopenssl/openssl< 1.0.1g-3+3
Ubuntuopenssl/openssl< 1.0.1f-1ubuntu2.1
NVDopenssl/openssl1.0.1g
NVDmariadb/mariadb10.0.010.0.13

Also affects: Fedora 19, 20

Patches

🔴Vulnerability Details

4
GHSA
GHSA-m249-hh62-97m2: Race condition in the ssl3_read_bytes function in s3_pkt2022-05-14
OSV
openssl vulnerabilities2014-05-05
CVEList
CVE-2010-5298: Race condition in the ssl3_read_bytes function in s3_pkt2014-04-14
OSV
CVE-2010-5298: Race condition in the ssl3_read_bytes function in s3_pkt2014-04-14

📋Vendor Advisories

5
Cisco
Multiple Vulnerabilities in OpenSSL Affecting Cisco Products2014-06-05
Ubuntu
OpenSSL vulnerabilities2014-05-05
BSD
FreeBSD-SA-14:09.openssl: OpenSSL use-after-free vulnerability2014-04-30
Red Hat
openssl: freelist misuse causing a possible use-after-free2014-04-08
Debian
CVE-2010-5298: openssl - Race condition in the ssl3_read_bytes function in s3_pkt.c in OpenSSL through 1....2010

💬Community

4
Bugzilla
CVE-2014-0221 CVE-2014-0198 CVE-2014-0224 CVE-2014-0195 CVE-2010-5298 CVE-2014-3470 mingw-openssl: various flaws [epel-7]2014-08-07
Bugzilla
CVE-2014-0221 CVE-2014-0198 CVE-2014-0224 CVE-2014-0195 CVE-2010-5298 CVE-2014-3470 openssl: various flaws [fedora-all]2014-05-09
Bugzilla
CVE-2014-0221 CVE-2014-0198 CVE-2014-0224 CVE-2014-0195 CVE-2010-5298 CVE-2014-3470 mingw-openssl: various flaws [fedora-all]2014-05-09
Bugzilla
CVE-2010-5298 openssl: freelist misuse causing a possible use-after-free2014-04-14
CVE-2010-5298 — Race Condition in Openssl | cvebase